Cross Domain Limitations With Ajax - JSON

前端 未结 4 801
无人共我
无人共我 2020-12-06 09:06

When requesting (ht|x)ml with ajax you can only send requests to the same domain. But if you request JSON you can send it to any domain. Why?

I\'m told it\'s for sec

4条回答
  •  我在风中等你
    2020-12-06 09:23

    Here is an example of why someone would hack an AJAX request.

    https://blog.codinghorror.com/preventing-csrf-and-xsrf-attacks/

    http://directwebremoting.org/blog/joe/2007/04/04/how_to_protect_a_json_or_javascript_service.html

提交回复
热议问题